Skip to content

🐛 fix(fuzz): size harness buffers to their input - #1235

Merged
gaborbernat merged 1 commit into
tox-dev:mainfrom
gaborbernat:fix/harness-exact-buffers
Oct 8, 2026
Merged

gaborbernat merged 1 commit into
tox-dev:mainfrom
gaborbernat:fix/harness-exact-buffers

Conversation

@gaborbernat

Copy link
Copy Markdown
Member

The IDNA and phone harnesses decoded UTF-8 into a block with one slot per input byte. A multibyte input decodes to fewer code points than bytes, so the engines got a buffer with spare slots past the last code point, and ASan missed a read into them. All three standalone harnesses, the JS one included, also gave an empty input one slot.

Each harness now counts the code points first and allocates that many, none for an empty input. The file readers allocate the file size, none for an empty file. libFuzzer copies each input into a heap block of Size bytes for the same reason, so ASan catches an overflow of it (FuzzerLoop.cpp).

With a harness patched to read one code point past the end, the old allocation let a multibyte and an empty input pass clean, and the new one stops both with a heap-buffer-overflow report. The fixed harnesses run the seed corpora and tox -e asan-js clean under ASan and UBSan.

The IDNA and phone harnesses decoded UTF-8 into one slot per input byte.
Multibyte input decodes to fewer code points than bytes, so the engines
read from a block with spare slots past the last code point, and ASan
missed any read into them. All three standalone harnesses also gave an
empty input one slot.

Count the code points first and allocate that many, and let an empty
input or file get a zero-size block. libFuzzer copies each input into a
block of its exact size for the same reason.
@gaborbernat gaborbernat added the bug Something isn't working label Oct 8, 2026
@codspeed

codspeed Bot commented Oct 8, 2026

Copy link
Copy Markdown

Merging this PR will regress 1 benchmark

⚡ 1 improved benchmark
❌ 1 regressed benchmark
✅ 579 untouched benchmarks
⏩ 32 skipped benchmarks1

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ test_feature[prune-shared-single] 89.1 µs 96.7 µs -7.88%
⚡ test_feature[shadow-slot-comments] 137.9 µs 110.1 µs +25.23%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing gaborbernat:fix/harness-exact-buffers (8a955de) with main (af31f20)

Open in CodSpeed

Footnotes

  1. 32 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@gaborbernat
gaborbernat merged commit 2d19343 into tox-dev:main Oct 8, 2026
54 of 63 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant